Information Security Analyst - GRC & Operations

WHSmith North America

Las Vegas (NV)

Hybrid

USD 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

WHSmith North America is seeking an Information Security Analyst to support and secure our cyber infrastructure while actively contributing to our Governance, Risk, and Compliance program. This hybrid role blends hands-on security operations with training and continuous control assessment responsibilities.

You will secure systems, partner with leaders to embed controls, deploy security solutions, and serve as a Tier 1 responder for alerts and remediations.

Qualifications

  • Bachelor of Science in Cybersecurity or related field, or equivalent hands-on experience.
  • 1–2 years of cybersecurity, IT, or GRC experience—or strong academic projects, certifications, or lab work.
  • Foundational understanding of NIST CSF, CIS Controls, ISO 27001, or PCI DSS; interest in continuous control assessments and compliance work.
  • Exposure to endpoint security or EDR tooling and a basic understanding of alert triage, escalation, and incident documentation; willingness to learn Tier 1 response workflows.
  • Familiarity with vulnerability scanning concepts, remediation tracking, user access reviews, and least-privilege principles.
  • Awareness of risk management and policy concepts, with an interest in supporting control assessments, evidence collection, and audit activities.
  • Interest in helping build and deliver cybersecurity awareness content (onboarding, annual, phishing simulations) and tracking basic training and phishing metrics.

Responsibilities

  • Secure the organization’s systems and information assets by applying cybersecurity best practices.
  • Partner with end users and department leaders to identify security needs and embed appropriate controls across business units.
  • Deploy, integrate, and configure new and existing security solutions in line with standard operating procedures.
  • Serve as a Tier 1 responder for cybersecurity alerts and remediations — triage, contain, elevate, document, and investigate problematic or anomalous activity.
  • Support vulnerability assessments and penetration testing and coordinate timely remediation of identified weaknesses.
  • Administer periodic access reviews to enforce least privilege.
  • Support the global cybersecurity compliance program, maintaining alignment with frameworks such as NIST CSF, CIS Controls, ISO 27001, and PCI DSS.
  • Perform continuous control assessments, document evidence, identify gaps, and report findings to key stakeholders.
  • Maintain the risk register, control catalog, and supporting policies, standards, and procedures; assist with internal/external audits, third‑party risk reviews, and ongoing monitoring.
  • Deliver corporate cybersecurity training — new‑hire onboarding, annual refreshers, role‑based training, and phishing simulations.
  • Manage training and awareness metrics (completion rates, click/report rates, repeat offenders, behavioral trends), report results to leadership, and coordinate remedial training with HR, IT, and managers.
  • Foster a culture of security consciousness across the organization.

Skills

Cybersecurity fundamentals
Security operations
Incident response
Vulnerability management
Access reviews
Risk & policy awareness
Security training delivery

Education

Bachelor of Science in Cybersecurity or related field

Tools

EDR tooling
Vulnerability scanning tools

Job description

As the Information Security Analyst, you will support and secure our current and future cyber infrastructure while playing a key role in our Governance, Risk, and Compliance (GRC) program. This hybrid role blends hands‑on security operations with compliance, training, and continuous control assessment responsibilities.

What You’ll Do
  • Secure the organization’s systems and information assets by applying cybersecurity best practices and protecting against unauthorized access, modification, or destruction.
  • Partner with end users and department leaders to identify security needs and embed appropriate controls across business units.
  • Deploy, integrate, and configure new and existing security solutions in line with standard operating procedures.
  • Serve as a Tier 1 responder for cybersecurity alerts and remediations — triage, contain, elevate, document, and investigate problematic or anomalous activity.
  • Support vulnerability assessments and penetration testing and coordinate timely remediation of identified weaknesses.
  • Administer periodic access reviews to enforce least privilege.
  • Support the global cybersecurity compliance program, maintaining alignment with frameworks such as NIST CSF, CIS Controls, ISO 27001, and PCI DSS.
  • Perform continuous control assessments, document evidence, identify gaps, and report findings to key stakeholders.
  • Maintain the risk register, control catalog, and supporting policies, standards, and procedures; assist with internal/external audits, third‑party risk reviews, and ongoing monitoring.
  • Deliver corporate cybersecurity training — new‑hire onboarding, annual refreshers, role‑based training, and phishing simulations.
  • Manage training and awareness metrics (completion rates, click/report rates, repeat offenders, behavioral trends), report results to leadership, and coordinate remedial training with HR, IT, and managers.
  • Foster a culture of security consciousness across the organization.
What You Bring
  • Education: Bachelor of Science in Cybersecurity or a related field, or equivalent hands‑on experience.
  • Experience: 1–2 years of experience or internships in cybersecurity, IT, or GRC — or a strong academic background with relevant projects, certifications, or lab work.
  • Frameworks & standards: Foundational understanding of common cybersecurity frameworks such as NIST CSF, CIS Controls, ISO 27001, or PCI DSS, and an interest in growing into continuous control assessments and compliance work.
  • Security operations & EDR: Exposure to endpoint security or EDR tooling and a basic understanding of alert triage, escalation, and incident documentation; willingness to learn Tier 1 response workflows.
  • Vulnerability & access management: Familiarity with vulnerability scanning concepts, remediation tracking, user access reviews, and least‑privilege principles.
  • Risk, policy & audit: Awareness of risk management and policy concepts, with an interest in supporting control assessments, evidence collection, and audit activities.
  • Security awareness & training: Interest in helping build and deliver cybersecurity awareness content (onboarding, annual, phishing simulations) and tracking basic training and phishing metrics.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Information Security Analyst
Information Security Analyst

Sylvan, Inc. • Detroit (MI)

On-site
USD 90,000 - 130,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Hybrid InfoSec: GRC & Operations Analyst
Hybrid InfoSec: GRC & Operations Analyst

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
Sr. Engineer, Governance, Risk & Compliance (TPRM)
Sr. Engineer, Governance, Risk & Compliance (TPRM)

NextGen Healthcare • Georgia

On-site
USD 85,000 - 110,000